just-a-mysql-mcp
This server provides a read-only interface for browsing MySQL database schemas and executing SQL queries, restricted to an allowlisted set of databases. It exposes three main functions:
list_tables: Returns the names of all tables in the bound database (no row data).describe_table: Returns column names and types for a specified table.mysql_query: Executes a single read-only SQL statement (SELECT,WITH…SELECT,SHOW,DESCRIBE/DESC, orEXPLAIN). Results are capped at 100 rows by default (configurable, maximum 1000), with truncation explicitly indicated.
Safety enforcement: all write operations (INSERT, UPDATE, DELETE, DDL) are rejected; only one statement per call is allowed; database access is limited to an allowlist, and a default database can be configured for unqualified requests. The server is designed to work with read-only MySQL user accounts.
Provides read-only access to a MySQL database, allowing to list tables, describe table schemas, and run read-only SQL queries (SELECT, SHOW, DESCRIBE, EXPLAIN) with a configurable row limit.
Click on "Install Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@just-a-mysql-mcpDescribe the users table"
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
just-a-mysql-mcp
Browse MySQL schema and run read-only SQL from your AI agent.
Read-only by design. Tools never INSERT / UPDATE / DELETE / DDL. An agent writing to the wrong table or environment can cause production-level incidents. Just because we can doesn't mean we should. Prefer a MySQL account that is itself read-only.
What it does
Database scope — Allowlist + Default Database for this process
List tables — names in one Allowlisted Database
Describe a table — columns and types (explicit Database + table)
Run a query — one read-only statement (
SELECT/WITH…SELECT,SHOW,DESCRIBE/DESC,EXPLAIN), with a hard row cap; visited Databases must be on the Allowlist
One MCP process is bound to an Allowlist of Databases (MYSQL_DATABASE: one name or a comma-separated list). Size one is strict single-Database; size many permits exactly those names.
Related MCP server: mcp-multi-db
Requirements
uv —
brew install uvMySQL 5.7+ / 8.x reachable over TCP
Setup
1. Clone and install
git clone https://github.com/xingyuli/just-a-mysql-mcp
cd just-a-mysql-mcp
uv sync2. Add to your AI agent
Single Database:
{
"mcpServers": {
"mysql": {
"command": "uv",
"args": [
"--directory", "/path/to/just-a-mysql-mcp",
"run", "mysql_mcp_server.py"
],
"env": {
"MYSQL_HOST": "127.0.0.1",
"MYSQL_PORT": "3306",
"MYSQL_USER": "readonly_user",
"MYSQL_PASSWORD": "secret",
"MYSQL_DATABASE": "your_database"
}
}
}
}Multiple Databases (stable Allowlist order; optional default override):
"env": {
"MYSQL_HOST": "127.0.0.1",
"MYSQL_PORT": "3306",
"MYSQL_USER": "readonly_user",
"MYSQL_PASSWORD": "secret",
"MYSQL_DATABASE": "app_dev,billing_dev",
"MYSQL_DEFAULT_DATABASE": "billing_dev"
}Shell exports work too:
"MYSQL_HOST": "${MYSQL_DEV_HOST}",
"MYSQL_USER": "${MYSQL_DEV_USER}",
"MYSQL_PASSWORD": "${MYSQL_DEV_PASSWORD}",
"MYSQL_DATABASE": "app_dev"3. Restart the agent and ask things like:
"What databases are in scope?"
"List tables in app_dev"
"Describe users in app_dev"
"Select the 10 most recent rows from …"
Configuration
Variable | Required | Default | Notes |
| No |
| |
| No |
| |
| Yes | ||
| Yes | No short alias | |
| Yes | One name or comma-separated Allowlist | |
| No | First name in | Must be on the Allowlist |
Safety summary
Rule | Behavior |
Writes | Rejected by the MCP; use a read-only DB user too |
Statements | Exactly one per |
Statement types |
|
Database scope | sqlglot visit check ⊆ Allowlist; unqualified → Default Database; |
Row cap | Default 100, max 1000; truncation is explicit |
Design notes: CONTEXT.md, docs/adr/0001-v1-design.md, docs/adr/0002-database-allowlist.md.
For local development and tests, see DEVELOPMENT.md.
Available Tools
3 toolsdescribe_tableA
Describe columns for one table in the bound database.
Args:
table: Unquoted table name (letters, digits, underscore)
| Name | Required | Description | Default |
|---|---|---|---|
| table | Yes |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries full responsibility for behavioral disclosure. It does not state whether the operation is read-only, how errors are handled (e.g., missing table), or what the output format looks like beyond mentioning the parameter constraint. The only behavioral hint is the parameter naming rule, which is more about parameter semantics.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is exceptionally concise: two sentences, front-loaded with the main purpose, followed by a parameter detail. No filler or redundant wording. Every sentence earns its place.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a simple single-parameter tool with an output schema, the description covers the essentials: purpose and parameter constraint. The output schema handles return values, so the description need not explain them. Missing usage guidelines and behavioral specifics are noted in other dimensions, but for its simplicity, the description is largely complete.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The schema has 0% description coverage, but the description compensates with a clear explanation of the 'table' parameter: 'Unquoted table name (letters, digits, underscore)'. This adds meaningful syntax details beyond the schema's generic title 'Table', helping the agent invoke the tool correctly. However, it could be more explicit about why quoting matters or provide an example.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's function: 'Describe columns for one table in the bound database.' The verb 'describe' plus the resource 'columns for one table' and scope 'bound database' is specific and distinguishes it from sibling tools like list_tables (lists tables) and mysql_query (runs queries).
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description implies the tool is used when you need column information for a specific table, but it does not explicitly mention when to use it versus alternatives or provide any exclusions. 'Describe columns for one table' gives context but no direct guidance on choosing this over list_tables or mysql_query.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
list_tablesA
List tables in the bound database. Returns table names only (schema browsing — no row data).
| Name | Required | Description | Default |
|---|---|---|---|
No parameters | |||
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
With no annotations, the description carries the full burden. It discloses the key behavior—returns only table names, no row data—and clarifies the scope ('bound database'). This is adequate for a simple listing tool, though it omits details like ordering or inclusion of views.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is two concise sentences, front-loaded with the core purpose and followed by a clarifying scope note. Every word earns its place with no redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
For a zero-parameter tool with an output schema available, the description sufficiently covers the essential behaviors: what it does, the scope (bound database), and what it returns (names only). No further detail is necessary.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
There are zero parameters, so the schema coverage is trivially 100%. The baseline for 0 params is 4, and the description adds no parameter information, which is appropriate since there are none to describe.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description clearly states the tool's function: 'List tables in the bound database.' It specifies the verb (List) and resource (tables), and distinguishes itself from siblings by clarifying it returns only table names, not schema details or row data.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description provides clear context: it is for schema browsing and explicitly notes 'no row data,' implying row queries should go to mysql_query. However, it does not explicitly name alternatives or state when not to use it, so it stops short of a 5.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
mysql_queryA
Run one read-only SQL statement against the bound database.
Allowed: SELECT (including WITH…SELECT), SHOW, DESCRIBE/DESC, EXPLAIN.
Results are capped (default 100 rows, max 1000); truncation is explicit.
Args:
sql: A single read-only SQL statement
limit: Max rows to return (default 100, max 1000)
| Name | Required | Description | Default |
|---|---|---|---|
| sql | Yes | ||
| limit | No |
Output Schema
| Name | Required | Description |
|---|---|---|
| result | Yes |
TDQS
Does the description disclose side effects, auth requirements, rate limits, or destructive behavior?
No annotations are provided, so the description carries the burden of behavioral disclosure. It explicitly states the operation is read-only, lists allowed statements, and discloses row cap and truncation behavior. This adds significant context beyond the basic action.
Agents need to know what a tool does to the world before calling it. Descriptions should go beyond structured annotations to explain consequences.
Is the description appropriately sized, front-loaded, and free of redundancy?
The description is concise and well-structured: a clear one-sentence purpose, a succinct 'Allowed' list, a note on row caps, and an args list. Every sentence adds value with no redundancy.
Shorter descriptions cost fewer tokens and are easier for agents to parse. Every sentence should earn its place.
Given the tool's complexity, does the description cover enough for an agent to succeed on first attempt?
With an output schema present, the description covers the tool's purpose, allowed operations, row-cap behavior, and parameter semantics. Minor gaps include no mention of error handling or interaction with sibling tools, but these are not essential given the overall clarity.
Complex tools with many parameters or behaviors need more documentation. Simple tools need less. This dimension scales expectations accordingly.
Does the description clarify parameter syntax, constraints, interactions, or defaults beyond what the schema provides?
The input schema has zero description coverage, but the description fully compensates by defining sql as 'A single read-only SQL statement' and limit as 'Max rows to return (default 100, max 1000)', adding clarity, constraints, and defaults for both parameters.
Input schemas describe structure but not intent. Descriptions should explain non-obvious parameter relationships and valid value ranges.
Does the description clearly state what the tool does and how it differs from similar tools?
The description opens with 'Run one read-only SQL statement against the bound database', providing a specific verb, resource, and scope. It lists allowed statement types and is clearly distinguishable from sibling tools like list_tables and describe_table, which focus on schema introspection.
Agents choose between tools based on descriptions. A clear purpose with a specific verb and resource helps agents select the right tool.
Does the description explain when to use this tool, when not to, or what alternatives exist?
The description states when to use the tool by listing allowed statement types (SELECT, SHOW, DESCRIBE, EXPLAIN) and noting result caps. It does not explicitly reference sibling tools or exclusion cases, but the context is clear enough for an agent to decide.
Agents often have multiple tools that could apply. Explicit usage guidance like "use X instead of Y when Z" prevents misuse.
Tool Schema Changelog
Recent tool additions, removals, and schema changes observed during successful MCP inspections. Dates show when Glama detected each change.
3 tool updates
v0.1.0- First observed
describe_table - First observed
list_tables - First observed
mysql_query
TDQS
The tools are mostly distinct in purpose: list_tables for table names, describe_table for column details, and mysql_query for arbitrary read-only SQL. However, mysql_query also supports DESCRIBE/DESC, creating a partial overlap with describe_table.
list_tables and describe_table follow a clear verb_noun pattern, but mysql_query deviates with a noun_verb structure. All names are snake_case and readable, so the inconsistency is minor.
Three tools is a minimal but well-scoped set for a read-only MySQL server. It is slightly on the small side, but each tool serves a distinct core need and the count fits the intentional minimalism.
The set covers the essential read-only workflow: discovering tables, inspecting schema, and running queries. Missing explicit tools for views/indexes are easily handled via mysql_query, so gaps are minor.
Maintenance
Resources
Unclaimed servers have limited discoverability.
Looking for Admin?
If you are the server author, to access and configure the admin panel.
Related MCP Connectors
Safe, read-only Postgres and MySQL access for AI agents. Audit log + column-level controls.
Read-only MCP server for turva.dev, an agent-readiness audit and advisory service.
Read-only MCP server exposing a user ORANO library to their own AI agent.
1Read-only MCP server for the OPERANT AI operating-agent calibration benchmark.
Related MCP Servers
- AlicenseAqualityCmaintenanceRead-only MySQL/MariaDB MCP server for running SELECT queries safely, with automatic read-only enforcement and query limits.314MIT
- AlicenseAqualityAmaintenanceRead-only MCP server for querying PostgreSQL, MySQL, and SQLite from AI agents — multi-database, safe by default.4181ISC
- AlicenseNot gradedqualityDmaintenanceA robust MCP server for interacting with MySQL databases through AI agents, providing tools for schema analysis, query execution, and dynamic connection management with read-only security.121MIT
- FlicenseNot gradedqualityFmaintenanceA read-only MCP server that enables AI agents to explore database schemas and execute safe queries on PostgreSQL and MySQL.-
Latest Blog Posts
- Who's Calling? MCP Hosts Are an Identity Blind Spot (And the Spec Knows It)By Om-Shree-0709 on .mcpAgent IdentityOAuth 2.1
- Your AI Chatbot Just Exposed Your CEO's Salary to an InternBy Om-Shree-0709 on .Agent IdentityMCP SecurityOAuth Delegation
- Why MCP Servers Need Execution Sandboxing (And Why Your Current Stack Isn't Enough)By Om-Shree-0709 on .Agentic AiPrompt InjectionWebAssembly
MCP directory API
We provide all the information about MCP servers via our MCP API.
curl -X GET 'https://glama.ai/api/mcp/v1/servers/xingyuli/just-a-mysql-mcp'
If you have feedback or need assistance with the MCP directory API, please join our Discord server